Posts Tagged ‘virus’

Trouble with js/downloader.agent

Posted By Harsh Singh on March 10th, 2010

http://magicalharsh.com/blog/trouble-with-jsdownloader-agent/

I don’t the how it happen , but since last few days whenever I opened my site , my AVG would pop up warning about some malicious javascript . I never paid much attention to this , afterall they even detect harmless keygens as trojans too  :P    . So I never took this seriously , hoping that everything will be fine in few days ( height of optimism ) .

But AVG kept on threatening me , and when my readers complained about this too , I got a little worried . I knew there was a javascript , and I know it was something related to a downloader agent . I knew where to start from . I google it straight away ( Bless google . Without you , we would be helpless ) . But mr. google failed as the only information I could gather that it was some phishing attack ( XSS , iframe ) but didn’t knew how to fix this problem .

Starting from scratch , I checked all my files for something “malicious” . And guess what I got . This bit of code was hiding in header.php .

No idea where this thing came from . Lesson learnt : always take your antivirus seriously and a XSS / iframe attack even more seriously .

Virus :: A folder is automatically created within all the folders with the same name as parent folder

Posted By Harsh Singh on March 7th, 2009


One of the most common viruses to affect your system . This virus
automatically creates a folder within folder with the same name as of parent folder . It appears again and again even if you delete it a thousand number of times .

More info about this virus

Name of the threat: W32.Netsky.P@mm
Command or file name: FVProtect.exe

Threat type: Spywaretrojan

Affected OS:
Win32 (Windows 9x, Windows XP, Windows Vista)

Intrusion Method

This threat copies its file(s) to your hard disk. Its typical file name is W32.Netsky.P@mm. Then it creates new startup key with name W32.Netsky.P@mm and value FVProtect.exe. You can also find it in your processes list with name FVProtect.exe or W32.Netsky.P@mm.

Solution

Download program for FVProtect.exe removal (True Sword Threat Remover)

Courtesy : http://www.securitystronghold.com/